Model or dataset
huytieu/COG-second-brain avatar
huytieu/COG-second-brain

cog-second-brain: the verifier only runs if you ask for it

Self-evolving second brain with 33 AI skills, 10 agents, and people CRM. Closed-loop harness: a V-model verification lifecycle where the worker never grades its own homework. Plus paired anti-slop design skills for marketing and product UI. Works with Claude Code, Cursor, Kiro, Gemini CLI, Codex.

1,255 stars151 forksHTMLMIT

At a glance

What is it?
COG-second-brain keeps its whole state in markdown files under git, with 33 skills and ten agents split between six workers and four read-only verifiers. Two things undercut the headline: the verification harness is opt-in, and two of the six agent platforms get seven of the thirty-three skills.
Who is it for?
COG-second-brain suits someone who already lives in markdown and git and wants their agent memory to be files they can read, diff and delete, because no database is the strongest thing here. Two things to accept before you rely on it.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly HTML, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 3, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The verification harness is opt-in, so ordinary requests are never verified

The central claim in the project description is a closed-loop harness in which the worker never grades its own homework. The architecture diagram is built around it: the skills delegate to six workers and are verified by four read-only verifiers, and the verifiers observe the markdown files rather than writing to them.

That is a good design. It is also not on by default.

The verification section says it is opt-in. Ask for one of those skills and work walks a V: the left side decomposes into falsifiable criteria, the apex is the build, and the right side verifies with evidence traced back to each criterion. Then the last sentence on the page says it plainly: say nothing and none of it runs, because ordinary work carries no gate.

So the worker-and-verifier separation is a capability you request, not a property the system has. A request that never mentions verification is executed by a worker with no independent check, and the six workers are still writing to the same files.

That is not a criticism so much as a design choice, and it is one a reader should know about. Anyone building on this needs to put the verification skill into their own default instruction path, because nothing in the kit does it for them. The `comprehensive-analysis` skill is the one entry that carries a duration estimate of roughly eight to twelve minutes, which is the sort of number you only see when a step is expected to be slow enough to notice.

Six agent platforms, six discovery conventions, one authoritative copy

The onboarding table is the clearest statement of what the project actually is: a set of skills shipped into whatever directory convention each agent reads.

| Agent | How it finds skills | |---|---| | Claude Code | `.claude/skills/` | | Antigravity | `.agents/skills/` + `.agents/rules/cog.md` | | Cursor | `.cursor-plugin/` + `.cursorrules` | | Kiro | `.kiro/powers/` | | Gemini CLI | `GEMINI.md` + `.gemini/commands/` | | OpenAI Codex | `AGENTS.md` |

Six platforms, six layouts, and 33 skills that have to reach all of them. The repository top level shows the result: `.agents/`, `.claude/`, `.claude-plugin/`, `.cursor-plugin/`, `.cursorrules`, `.gemini/`, `.kiro/` and two instruction files at once, `AGENTS.md` and `CLAUDE.md`, plus `GEMINI.md`.

The duplication is acknowledged rather than hidden. Antigravity is described as using a pointer-stub format where thin stubs in `.agents/` delegate to the `.claude/` playbooks, which stay authoritative. So one surface holds the real content and the rest are references.

That makes drift the obvious failure mode, and the project ships a guard for it: `./scripts/validate-agent-surface.sh`, to be run before publishing or updating framework files, described as catching drift between manifests, documentation and shipped files.

Installation is either a clone followed by opening the directory in your agent, or a single command:

bash
npx skills add huytieu/COG-second-brain

After onboarding, the page claims the system is personalised in about two minutes.

Two platforms get seven of the thirty-three skills

The support matrix is more honest than the feature tables, and it is the only place the numbers are broken down.

| Surface | Support | |---|---| | Claude Code | 33 native skills + 10 agents | | Antigravity | 33 skills + 10 agents, pointer-stub format | | Agent Plugins standard | root `plugin.json` + `skills/`, spec 1.0.0 conformant | | Cursor | plugin manifest + rules | | Kiro | 7 native powers | | Gemini CLI | 7 native commands | | `AGENTS.md` | 33 documented commands |

So there are three tiers. Two platforms get everything. Cursor gets a manifest and rules. Kiro and Gemini CLI get seven items each, labelled as core workflows today, which is the phrase a project uses when it means the rest is not there yet.

The agent count is stated the same way everywhere it appears: ten agents, made of six workers and four verifiers. That one is consistent.

The skill total is what varies in emphasis. Thirty-three appears in the diagram, in the repository description, in the Claude Code row, in the Antigravity row and in the `AGENTS.md` row. The two rows that say seven are the ones nobody quotes.

There is also a plugin standard in play. A root `plugin.json` alongside a `.claude-plugin/` directory, described as conformant with version 1.0.0 of a published agent plugin specification, so any client that understands the standard can load the kit as a plugin. A `marketplace-entry.json` sits at the top level next to it.

Memories carry a last-verified stamp because staleness is designed in

The core skills reveal how the system thinks about knowledge that can go out of date.

The `memory-hygiene` skill is a trust sweep of persistent memory. It re-verifies claims against the live environment and stamps `last_verified` plus a confidence value. That is a schema decision, not a prompt: a stored assertion carries when it was checked and how sure the system was.

Two other entries are explicit about time windows. The `daily-brief` skill is verified news intelligence with a seven-day freshness constraint, and `comprehensive-analysis` is a deep seven-day analysis for weekly reviews or board preparation.

So the design assumes memory rots and news expires, and it handles both by making the age of a claim part of the claim. That is the difference between a second brain that accumulates and one that can be audited.

The rest of the core skills are ordinary capture and consolidation work: `braindump` for raw thoughts with automatic classification, `url-dump` for links with extracted insights, `weekly-checkin` for cross-domain pattern analysis, `knowledge-consolidation` for building frameworks out of scattered notes, and `onboarding` to run first.

There is also `update-cog`, described as updating the framework files without touching your content. That separation is the load-bearing property of a system that rewrites its own configuration, and it is the one worth testing before you trust it.

Seven numbered folders, and no database anywhere

The vault is seven directories with numeric prefixes, and they are at the repository root rather than inside a config folder.

`00-inbox/`, `01-daily/`, `02-personal/`, `03-professional/`, `04-projects/`, `05-knowledge/` and `06-templates/`.

The naming is PARA-shaped with an inbox and a templates folder added, and the zero-padded numbering means alphabetical order is also workflow order. It is a legible choice and it means the whole structure is visible in a file listing before you read any documentation.

The storage claim is the other half. The project describes itself as cognition plus Obsidian plus git, with no database and no vendor lock-in, just markdown files. The architecture diagram shows the same idea: skills read and write markdown, the markdown goes to git and to iCloud, and the skills sync with GitHub, Linear, Slack and PostHog.

That list is worth pausing on. PostHog is product analytics, Linear is issue tracking, Slack is chat, and GitHub is source control. So the integrations are not only about storage; the team-intelligence skills cross-reference those four to build a daily brief, with two-way sync back to Linear.

No database means no schema to migrate and no query language to learn. It also means every capability, including the memory trust sweep and the last-verified stamps, is implemented in files you can open, grep and put under version control.

Antigravity is listed as a first-class surface without a link

The compatibility line at the top of the page is a list of hyperlinks, with one exception.

> Works with Claude Code • Antigravity • Cursor • Kiro • Gemini CLI • OpenAI Codex • any AI that reads markdown

Claude Code, Cursor, Kiro, the Gemini CLI and Codex each carry a URL. Antigravity appears as plain text in the same list, with no link, and it is the second entry rather than an afterthought at the end.

That matters because Antigravity is not a footnote in the rest of the documentation. The support matrix calls it a full first-class surface, equal to Claude Code, with all 33 skills and all 10 agents in pointer-stub format, and the architecture claims that the `.agents/` stubs delegate to the `.claude/` playbooks.

So the project treats it as fully supported while giving a reader no way to find out what it is or where to get it. Anyone deciding whether to run this on Antigravity has to take the claim on trust.

Two smaller artefacts in the repository root relate to this. There is a root `plugin.json` for the general agent plugin standard and a separate `.claude-plugin/` directory for Claude Code, and a `marketplace-entry.json` beside them. Three files describing where a skill can be installed from is one more than most projects need, and it is the kind of thing the surface validation script exists to keep consistent.

Versions move in steps of two and five, and a shell script does the update

The release titles read like a changelog of intentions rather than of fixes.

v3.8.1 on 2026-07-27 is Paired Anti-Slop Design Skills. v3.10.0 on 2026-08-07 is Agent Plugins Standard. v3.15.0 on 2026-10-02 is Controlled Language.

Ten weeks, three releases, and the version numbers jump by two and then by five rather than by one. That pattern says a release happens per feature rather than per batch, which fits a kit whose whole model is a set of skills that each add up.

Controlled Language is the one that sounds like a policy change rather than a feature. Nothing on the visible page explains what it governs, and a project with a paired anti-slop design skill for marketing and product UI is plausibly about controlling how the agent writes. Worth reading the changelog entry for before relying on the current wording of anything.

Updates are a shell script at the root, `cog-update.sh`, and the skill surface is validated by `scripts/validate-agent-surface.sh` before framework files are published or updated. There is a `COG-VERSION` file at the top level alongside the two changelog-bearing files, `CHANGELOG.md` and `WORKFLOW.md`, and a `SETUP.md` for optional configuration covering git sync, iCloud and Obsidian Tasks.

The last push to the repository is dated 2026-09-28.

Editorial conclusion

COG-second-brain suits someone who already lives in markdown and git and wants their agent memory to be files they can read, diff and delete, because no database is the strongest thing here. Two things to accept before you rely on it. The worker never grading its own homework only happens when you ask for the verification harness, so the default behaviour of a normal request is unverified. And the six agent surfaces are not equal: Claude Code and Antigravity get the full set, while Kiro and Gemini CLI get seven workflows out of thirty-three. If you run either of those two, check which skills you actually lose. The numbered vault layout, the last-verified stamps on memory and the surface validation script are all signs of a project that has thought about its own failure modes.

Frequently asked questions

Does COG-second-brain verify the work an agent does?

Only when you ask. The verification harness is opt-in: request it and work walks a V from falsifiable criteria through the build to evidence traced back to each criterion. Say nothing and none of it runs, so ordinary work carries no gate.

How many skills and agents does COG-second-brain ship?

33 skills and 10 agents, made of 6 workers and 4 read-only verifiers. Kiro and Gemini CLI get 7 native powers or commands rather than the full set, which the support matrix labels as core workflows today.

Where does COG-second-brain store its data?

In markdown files under version control, with no database. The vault is seven numbered folders, `00-inbox/` through `06-templates/`, and the architecture sends the files to git and to iCloud.

How does COG-second-brain know when a memory is out of date?

The `memory-hygiene` skill re-verifies claims against the live environment and stamps `last_verified` plus a confidence value. The daily brief also carries a seven-day freshness constraint.

Which coding agents does COG-second-brain support?

Claude Code and Antigravity get the full surface, Cursor gets a plugin manifest and rules, Kiro and Gemini CLI get core workflows, and `AGENTS.md` is the universal fallback for Codex and anything else that reads markdown.

Official sources

  1. huytieu/COG-second-brain on GitHub
  2. Issues
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/huytieu-cog-second-brain.svg)](https://hysenlabs.com/projects/huytieu-cog-second-brain)